Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 11: DLA-4352-1 python-authlib Important Security Threats

debian lts
Calendar Grey October 29, 2025
Dist Debian Esm H88
Multiple vulnerabilities discovered in python-authlib require immediate attention for Debian LTS users to ensure security.
Multiple vulnerabilities have been found in python-authlib, a Python library for OAuth and OpenID Connect servers

Summary

Multiple vulnerabilities have been found in python-authlib, a Python
library for OAuth and OpenID Connect servers.

CVE-2024-37568

Unless an algorithm is specified in a jwt.decode call, HMAC verification
is allowed with any asymmetric public key.

CVE-2025-59420

Authlib’s JWS verification accepts tokens that declare unknown critical
header parameters (crit), violating RFC 7515 “must‑understand” semantics.
An attacker can craft a signed token with a critical header that strict
verifiers reject but Authlib accepts. In mixed‑language fleets, this
enables split‑brain verification and can lead to policy bypass, replay,
or privilege escalation.

CVE-2025-61920

Authlib’s JOSE implementation accepts unbounded JWS/JWT header and
signature segments which can lead to a DoS during verification.

CVE-2025-62706

Authlib’s JWE zip=DEF path performs unbounded DEFLATE decompression
which can lead to a DoS.


Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Package: python-authlib
Version: 0.15.4-1+deb11u1
CVE ID: CVE-2024-37568 CVE-2025-59420 CVE-2025-61920 CVE-2025-62706

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here